How do I run a pcap on Azure Firewall?

Kryptic Dwarf 0 Reputation points
2024-11-27T17:39:19.4866667+00:00

I am trying to build a non Meraki VPN tunnel to a Meraki vMX appliance that sits behind an Azure Firewall. I suspect that I am missing a Network or DNAT rule to allow interresting traffic. I need visibility on the traffic flow to understand why traffic is not making it to the vMX appliance.

Is there an option for me to run a debug directly on the Azure Firewall?

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
703 questions
Azure Firewall Manager
Azure Firewall Manager
An Azure service that provides central network security policy and route management for globally distributed, software-defined perimeters.
97 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Rohith Vinnakota 1,515 Reputation points Microsoft Vendor
    2024-11-27T21:59:09.7466667+00:00

    Hi Kryptic Dwarf,

    Welcome to Microsoft Q&A Platform. Thank you for reaching out & hope you are doing well.
     

    Azure Firewall does not support direct packet capture (pcap) or debugging directly on the firewall itself.  Azure Firewall provides diagnostic logs that can help you understand traffic flow and identify any issues.  
    Steps to Enable Diagnostic Logging:

    1. Navigate to the Azure Firewall resource in the Azure portal.
    2. Select "Diagnostics settings" under the Monitoring section.
    3. Click on "Add diagnostic setting".
    4. Select the log categories you want to enable (Application Rule Log, Network Rule Log, etc.).
    5. Choose where to send the logs (Log Analytics workspace, Storage Account, or Event Hub).

    Refer this link : Monitor Azure Firewall | Microsoft Learn

    Thanks,

    Rohith

    Please don’t forget to close the thread by clicking "Accept the answer" wherever the information provided helps you, as this can be beneficial to other community members.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.